Executive brief
GitLab Enterprise Edition contains a security flaw that allows an authorized user to view or change the cleanup settings for another group's virtual registry. This could lead to unauthorized modifications of data retention policies or the exposure of internal configuration settings. Organizations should update to the latest patched versions to ensure proper isolation between different user groups.
Technical details
An authorization bypass vulnerability (CWE-639) exists in the Virtual Registry Cleanup Policy API of GitLab EE. The flaw stems from insufficient authorization checks when accessing or modifying cleanup policies, allowing an authenticated attacker to manipulate settings belonging to other groups by providing a user-controlled key. The vulnerability affects versions 18.6 through 18.11.5, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. It has been remediated in versions 18.11.6, 19.0.3, and 19.1.1.
Affected products
- GitLab GitLab Enterprise Edition 18.6 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1
Timeline
- 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, and 18.11.6
- 2026-06-25: advisory: NVD published the CVE record